Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.3.x (compat)

CIS
linux/amd64
debian 13
Tags:

8-compat, 8-debian-compat, 8-debian13-compat, 8.3-compat, 8.3-debian-compat, 8.3-debian13-compat, 8.3.11-compat, 8.3.11-debian-compat, 8.3.11-debian13-compat

Index digest:

sha256:afc087fed6c922255c76da49b4c8dc238d4c40cf7af3167159350bed91cd4a74

Manifest digest:

sha256:92fea361c8e9dc03e851176d3e95013df527cc5851b7019254ce53f96cf87797

Size

174.38 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:f12fe7044c786d56a909b282115ca25c2141b5d3a0525916543fbf45bad74d29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:a388f0c211842af24537dd104caa05701816d20b171d4d49a4d3574ae8f56c57
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:e16e4b77f01ad88c3897641f6242afa23ccb32a9a500d5aca53b0097f6c2ac93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:f357e09adfae3df08657a9611a213e581f9d564189ea86b1fe550b60b390d08e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:a95c9d9a64351f1ef575cd24c43e7ffb9e52b5e006bdd45867583619edaf8ed2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:9187ccbd88ccf2da6e32d3b6b22d6f639d7f6a15a7652a7012a67a843928b59d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:c2d99f36eff6f702a64d52e7911d73e73bc8e38917243b6bcdbd378cb867383c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:c6fd31b1db5d78e6c0cd1ae94ee92a1ba59e1f19b247358bd6d75f27406aa886
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:fd9c0305c709839821ef13b94c37a8f948e4b1ff2546a2ccc9ddc9f5ad746036
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:98d4ef4c43cc78e8e301c4ab31f5225a96656ed277ed58af6003a3e8d5b28730
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:f8cfa4ab3983be2ed90fbd185b65aa6a9c70564d604a6b0b6b89374831b14fe0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:0011cfd5edf1b2102065e8d7cb12c86c155e02419cbb5907b8ad0831a99517ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:8aae6415df42f4df9d03003bf37978f8d36e1d2ed0aa23e82beccd0afc0e598f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:556abd48adcbbf5d05c033b417ffa818ca46934fdcd446523e19fc7c08a7f618
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:a9098958011ec689dc51696890078e028f61247396cdb9db83cdfe9668b207f9